Applies to: Customers using a paid workspace or managed service · Updated 13 September 2026
Controller and processor roles
For a website enquiry, smbf.me normally acts as controller and the privacy notice applies. Where a customer workspace or managed service requires smbf.me to process personal data only on the customer's documented instructions, smbf.me may act as processor and an Article 28 DPA is agreed before that processing begins.
When a DPA is needed
The signed order and DPA define the subject matter, duration, nature and purpose of processing, data categories, people concerned, and the rights and duties of the customer.
Core commitments
- Process customer data only on documented instructions and notify the customer if an instruction appears unlawful.
- Keep authorised people bound by confidentiality and apply documented technical and organisational security measures.
- Use subprocessors only under the agreed authorisation route and bind them to equivalent obligations.
- Assist with data-subject requests, security incidents, breach notification, impact assessments, and regulator communications where required.
- Provide information needed for compliance and agreed audits.
- Address international transfers through the agreed lawful mechanism.
- Return or delete customer data at the end of the service, subject to documented legal retention duties.
Subprocessors
Any processor used for a customer workspace is disclosed through the subprocessors page and the applicable contract. We seek authorisation and require equivalent data-protection obligations.
Scope boundary
This public page is a summary, not a signed DPA. Ask hello@smbf.me for the agreement that matches your proposed service and data flow.